Identity Server Assertion via Statistical Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securely and reliably asserting identity information across untrusted networks, particularly in verifying the validity of identity sources.

Innovation Solution

A system and method utilizing an identity server with a processor, communication interface, and storage medium to receive, verify, and store identity document information, creating an electronic record that can be shared with untrusted entities for verification, while ensuring the validity of the identity information through statistical probability matching and additional document verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity information is shared across untrusted networks, then identity verification can be performed, but the reliability and security of the identity assertion deteriorates

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoiduntrusted network security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third party (identity server) that acts as an intermediary between the entity asserting identity and the verifier. The server receives identity documents, validates their format and content, creates electronic records, and releases verified identity information to untrusted entities. This mediator approach isolates the untrusted network from direct identity assertion risks while enabling verification functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of identity documents before they are shared with untrusted entities. The identity server verifies document format matches expected patterns, extracts information, and creates electronic records in advance. This preliminary action ensures that only validated identity information is released, maintaining reliability even when communicating through untrusted networks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If additional identity documents are required for verification, then the reliability of identity assertion improves, but the complexity of the verification process increases

Engineering Contradiction:
Improveidentity assertion reliabilityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity server automatically handles the complex verification process without requiring manual intervention. It autonomously receives identity documents, validates formats, extracts information, determines minimum document requirements, and releases verified data. This self-service approach maintains high reliability through comprehensive verification while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts verification parameters based on the type and reliability of identity documents received. When high-reliability documents are provided, the system accepts fewer documents; when lower-reliability documents are received, it requests additional verification materials. This parameter adaptation maintains reliable verification while simplifying the user experience.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If identity documents are verified through format matching, then the speed of verification improves, but the precision of identity validation may deteriorate

Engineering Contradiction:
Improveverification speedVSAvoididentity validation precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs partial verification through format matching to achieve rapid initial validation, then supplements this with additional checks based on the document type and risk assessment. This partial action approach enables fast verification for standard documents while maintaining precision through targeted additional validation when needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The identity server uses feedback loops to refine verification precision. It monitors the reliability of identity assertions and adjusts verification depth accordingly. When format matching indicates potential issues or when high-stakes verification is detected, the system requests additional information or performs more rigorous validation, balancing speed and precision dynamically.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12079315B2System and method for identity creation and assertion
Publication Date: 2024.09.03 TOPPAN SECURITY SAS
  • US12079315B2 patent drawing
  • US12079315B2 patent drawing
  • US12079315B2 patent drawing

AI summary

A system is disclosed that includes an identity server that is configured to build, manage, augment, and assert a user's identity. The identity server may also be configured to manage attestations for the user's identity.